CDE XTerm Elevated Privilege Acquisition Vulnerability
BID:3646
Info
CDE XTerm Elevated Privilege Acquisition Vulnerability
| Bugtraq ID: | 3646 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 06 2001 12:00AM |
| Updated: | Dec 06 2001 12:00AM |
| Credit: | This vulnerability was announced in a Caldera Security Advisory on December 06, 2001. |
| Vulnerable: |
Caldera UnixWare 7.1.1 Caldera UnixWare 7.1 .0 Caldera OpenUnix 8.0 |
| Not Vulnerable: | |
Discussion
CDE XTerm Elevated Privilege Acquisition Vulnerability
Common Desktop Environment (CDE) is a commercial window management system for X. It is distributed with various commercial UNIX implementations.
CDE does not check the validity of previously saved session. This vulnerability allows a local user to make modifications to the previously saved CDE session, and when the desktop restarts, give the user an xterm with elevated privileges. This could allow a local user to gain elevated privileges, including administrative access.
Common Desktop Environment (CDE) is a commercial window management system for X. It is distributed with various commercial UNIX implementations.
CDE does not check the validity of previously saved session. This vulnerability allows a local user to make modifications to the previously saved CDE session, and when the desktop restarts, give the user an xterm with elevated privileges. This could allow a local user to gain elevated privileges, including administrative access.
Exploit / POC
CDE XTerm Elevated Privilege Acquisition Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
CDE XTerm Elevated Privilege Acquisition Vulnerability
Solution:
Vendor fixes available:
Caldera UnixWare 7.1 .0
Caldera UnixWare 7.1.1
Caldera OpenUnix 8.0
Solution:
Vendor fixes available:
Caldera UnixWare 7.1 .0
-
Caldera erg711820.Z
ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.37/erg7118 20.Z
Caldera UnixWare 7.1.1
-
Caldera erg711820.Z
ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.37/erg7118 20.Z
Caldera OpenUnix 8.0
-
Caldera erg711820.Z
ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.37/erg7118 20.Z
References
CDE XTerm Elevated Privilege Acquisition Vulnerability
References:
References: